SUSPICIOUS — kumus.pdf
SUSPICIOUS — kumus.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f8439b69ad103a8d7bca46975ac70531d39710b9ad5a9671d967d7bfc1c33090 - SHA-1:
4edbe45389aa43fc9804f70e2ab2dc3ef2951528 - MD5:
966e9fbccbe98f86b187c8c2af253f4c - ssdeep:
384:OsFlS3K6XgKV7cAgdOpW+043zcevxuweQ6K7NUja3xKrbAGhGl1sCUSjZJR3NKmb:ugGzpD73Yeh7NUjaMXAumcaWSIeD1/ - TLSH:
T157308EF78453ED8C6682AB036EFA245C508AD68D6032EB6458E8366DC47C3FD3F40961 - Submitted as: kumus.pdf
- File type: pdf · Size: 36665 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/28c37048-1822-4410-b735-2f930ec51c89/razuten.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=bruce+almighty++free, https://site-1036869.mozfiles.com/files/1036869/jizawiwibodilapejarevi.pdf, https://site-1038468.mozfiles.com/files/1038468/tujimiduz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=bruce+almighty++free
- https://site-1036869.mozfiles.com/files/1036869/jizawiwibodilapejarevi.pdf
- https://site-1038468.mozfiles.com/files/1038468/tujimiduz.pdf
- https://site-1036689.mozfiles.com/files/1036689/2483523637.pdf
- https://site-1038605.mozfiles.com/files/1038605/26751625122.pdf
- https://site-1037022.mozfiles.com/files/1037022/66862531919.pdf
- https://uploads.strikinglycdn.com/files/28c37048-1822-4410-b735-2f930ec51c89/razuten.pdf
- https://cdn.shopify.com/s/files/1/0460/6951/4404/files/union_city_last_stand_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0492/0206/9667/files/74224260269.pdf
- https://cdn.shopify.com/s/files/1/0431/5794/6522/files/resumen_de_la_investigacion_en_mexico_y_su_evolucion_social.pdf
- https://cdn.shopify.com/s/files/1/0486/2135/5173/files/ejemplos_de_un_ensayo_de_comparacion_y_contraste.pdf
- https://site-1040777.mozfiles.com/files/1040777/53194182326.pdf
- https://site-1036742.mozfiles.com/files/1036742/bozibotufanawepineri.pdf
- https://site-1040299.mozfiles.com/files/1040299/modosatop.pdf
- https://site-1036779.mozfiles.com/files/1036779/dovufigizowazip.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036869.mozfiles.com
- site-1038468.mozfiles.com
- site-1036689.mozfiles.com
- site-1038605.mozfiles.com
- site-1037022.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040777.mozfiles.com
- site-1036742.mozfiles.com
- site-1040299.mozfiles.com
- site-1036779.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report